Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 07 Feb 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw was found in puppet-agent. Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. | Utilization of a module presented a security risk by allowing the deserialization of untrusted/user supplied data. This is resolved in the Puppet Agent 7.4.0 release. |
Title | puppet-agent: Deserialization of untrusted data | Deserialization of untrusted data |
References |
|

Status: PUBLISHED
Assigner: Perforce
Published: 2025-02-07T19:28:45.531Z
Updated: 2025-02-07T19:46:31.091Z
Reserved: 2021-02-09T22:41:26.424Z
Link: CVE-2021-27017

Updated: 2025-02-07T19:46:24.940Z

Status : Received
Published: 2025-02-07T20:15:31.983
Modified: 2025-02-07T20:15:31.983
Link: CVE-2021-27017
